A workshop pegboard covered with dozens of labelled self-service tools, a hand taking a screwdriver and a small unattended cash tray underneath

August 30, 2026 · 6 min read

By Thomas Cohen, founder of Maestro

Self-service skills: the supply chain nobody is watching

The github/spec-kit repository shows 130,054 stars a year after launch. The AI agent skills ecosystem is growing just as fast, and installing a skill on demand is becoming the new curl piped into a terminal.

The github/spec-kit repository shows 130,054 stars a year after its August 21, 2025 launch (api.github.com/repos/github/spec-kit, checked August 18, 2026). The AI agent skills ecosystem has been growing at the same pace since October 2025. Installing a skill on demand is becoming the new curl piped into a terminal.

Why a skill installed on demand is a risk

A skill is instruction text given to an AI agent, sometimes accompanied by scripts executed on your behalf. When it comes from a third-party directory, installed at the moment of need, nobody has checked its contents, licence or what it actually executes before you. It is exactly the pattern that made ‘curl piped into a terminal’ notorious among developers: code executed before being read because a tutorial asks for it.

Maestro's opposite choice

Rather than a registry to browse on demand, Maestro vendors its expertise: every skill is copied into the product repository, pinned to a precise version of its original repository, with an MIT licence checked entry by entry in a catalogue. Nothing installs on demand while an agent works for you; everything has already been reviewed, frozen and audited before being offered.

The strict rule enforced by our own continuous integration

A technical rule protects this choice over time: Markdown only, never a vendored scripts directory. This constraint is checked automatically on every catalogue change, not merely promised in documentation. A skill wanting to execute arbitrary code on your behalf simply cannot enter the catalogue as it stands.

What ‘best skills’ lists leave out

Directories listing large numbers of skills focus on volume and discoverability, rarely on provenance or average content quality. None publishes a systematic audit policy comparable to continuous integration blocking a non-compliant skill before catalogue entry. The difference is not visible at first glance: a poorly audited skill and a vendored one often look the same in a conversation, making vigilance all the more necessary from the product vendor.

What this changes for you

You never see the mechanics of expertise injected into your agents: that is Maestro's very principle, remaining the deliberate opposite of a terminal. But knowing every component of your agent team's intelligence has traceable provenance, a checked licence and frozen content, rather than a script downloaded on demand from an anonymous directory, changes the nature of the trust you place in the tool, even if you never read a line of that expertise yourself.

Caution still applies

Vendoring does not make a skill infallible: expertise may remain imperfect or poorly suited to your specific case, even pinned to a clean SHA and reviewed before integration. That is why every document produced remains subject to your own approval before it truly counts, regardless of the quality of the expertise that informed it behind the scenes.

Back to the journal

Take the baton.

Leave your email to try Maestro in the first waves.

The beta opens in waves. People on the list try it first, and Maestro stays free throughout the beta.

The beta is currently available on macOS 13 or later. Your answer helps us plan other versions.

Your email is only used to let you know when access opens. Nothing else, we promise.